# Zbtlink router ENDLESSDOORS backdoor discovery

> Live situation record from CLSTR: https://clstr.news/situations/zbtlink-router-endlessdoors-backdoor-discovery
> Updated: 2026-08-10T08:43:13.000Z. Sources: 15. Developments: 2.

Security researchers at VulnCheck identified a malicious implant named ‘ENDLESSDOORS’ embedded in router models manufactured by Shenzhen-based Zbtlink Electronics (also known as Shenzhen Zhibotong Electronics). The vulnerability, discovered in devices such as the Zbtlink AX3000 Dual SIM 5G CPE WiFi 6 router, allows for unauthorized remote Linux control with root privileges.

The implant functions by using a modified ‘rctl’ tool to act as both a client and server, hiding among processes named ‘kworker’. Because the device initiates outbound connections, it can bypass firewalls and NAT settings. In one instance, the device made unauthorized connections even while on an isolated research network.

Zbtlink has suspended sales of affected models and is developing patches, claiming the code was intended as an “after-sales technical-support tool,” though researchers argue it was deliberately hidden. Analysts estimate at least 100,000 routers are deployed worldwide. The discovery has prompted security advisories from the Canadian government and drawn attention to existing U.S. FCC restrictions on Chinese consumer routers.

## Timeline

### 2026-08-10: Zbtlink routers found with embedded spyware component

Researchers discovered ‘ENDLESSDOORS’, a malicious component in Zbtlink and Wiflyer routers that allows remote root access via unauthorized outbound connections to external servers.

2 sources. https://clstr.news/cluster/zbtlink-routers-found-with-embedded-spyware-component

### 2026-08-06: Zbtlink routers harbor factory-installed ENDLESSDOORS backdoor

Zbtlink routers (≥20 models, CVE‑2026‑66747) contain a factory‑installed ENDLESSDOORS backdoor that gives root access, contacts a China‑registered domain every 35 seconds, and affects an estimated 100,000 units

13 sources. https://clstr.news/cluster/tp-link-omada-zerotouch-provisioning-vulnerabilities-enable-fleetscale-takeover

---
Cite as: Zbtlink router ENDLESSDOORS backdoor discovery. CLSTR, https://clstr.news/situations/zbtlink-router-endlessdoors-backdoor-discovery
